GDPR Fines and Penalties: Latest Enforcement Tracker (2026)

By Recording Law Editorial TeamReviewed September 3, 202621 min read
GDPR Fines and Penalties: Latest Enforcement Tracker (2026)

Frequently Asked Questions

What is the maximum GDPR fine?

The maximum GDPR fine is EUR 20 million or 4% of the organization's total worldwide annual turnover from the preceding financial year, whichever is higher. This upper-tier penalty applies to violations of core processing principles, data subject rights, consent rules, and international transfer requirements under Article 83(5). For lower-tier violations such as record-keeping and DPO appointment failures, the maximum is EUR 10 million or 2% of global turnover.

What is the largest GDPR fine ever issued?

The largest confirmed GDPR fine is EUR 1.2 billion, imposed on Meta Platforms Ireland Limited by Ireland's Data Protection Commission in May 2023 for transferring EU Facebook user data to the United States without adequate safeguards. The fine resulted from an EDPB binding decision. Meta has appealed to the EU General Court; the appeal remains pending as of 2026. The second-largest fine on record is the Dutch AP's EUR 824,990,000 penalty against Uber, imposed on August 21, 2026 for fully automated driver deactivations; Uber has appealed. Amazon's EUR 746 million fine, which previously held second place, was annulled by a Luxembourg court in March 2026 and sent back to the regulator for reassessment.

Can a company be fined under GDPR without any intent to break the rules?

No. The CJEU confirmed in its December 2023 Deutsche Wohnen judgment (Case C-807/21) that GDPR fines require the infringement to have been committed intentionally or negligently. Strict liability is incompatible with Article 83. However, negligence is a low bar: failing to take reasonable compliance steps will generally satisfy it. An organization that makes a genuine, documented effort to comply but still makes a mistake has a viable argument for a reduced fine.

How are GDPR fines calculated?

Supervisory authorities follow the EDPB Guidelines 04/2022, which establish a five-step process: identify the infringements and evaluate Article 83(3) on multiple violations; determine a starting amount based on nature, gravity, and duration and the organization's turnover; evaluate aggravating and mitigating factors including intent, cooperation, prior violations, data categories, and remediation steps; apply the legal maximum for the relevant tier; and assess whether the final amount is effective, proportionate, and dissuasive.

Can GDPR fines apply to companies outside the EU?

Yes. The GDPR applies to any organization worldwide that processes personal data of people in the EU, and fines apply equally to non-EU companies. TikTok (China-owned, EUR 530 million via Irish DPC), Amazon (US-based, EUR 746 million via Luxembourg CNPD, now annulled on appeal), and Uber (US-based, EUR 290 million in 2024 and EUR 824,990,000 in 2026, both via the Dutch AP) have all received major fines despite being headquartered outside the EU.

What happened to Amazon's EUR 746 million GDPR fine?

Amazon's EUR 746 million fine, imposed by Luxembourg's CNPD in 2021 for using an invalid legal basis for behavioral advertising, was annulled by Luxembourg's Administrative Court on March 12, 2026. The court found the CNPD had failed to analyze whether Amazon acted intentionally or negligently: the fault requirement the CJEU established in Deutsche Wohnen, and had not considered whether a less severe measure was appropriate. The substantive finding that Amazon's legal basis was invalid was upheld. The case was referred back to the CNPD to redo its analysis; Amazon may still face a new fine.

Can individuals sue for GDPR violations?

Yes. Article 82 gives individuals the right to seek compensation from controllers or processors for material and non-material damage caused by a GDPR infringement. The CJEU confirmed in the Österreichische Post case (C-300/21, May 2023) that there is no minimum seriousness threshold: any proven distress can qualify for compensation. However, claimants must prove an actual infringement, actual damage, and a causal link. Regulatory enforcement and civil claims can proceed simultaneously.

Which EU country issues the most GDPR fines?

Spain's Agencia Española de Protección de Datos (AEPD) issues the highest volume of individual fines, over 1,000 since 2018, mostly smaller penalties targeting domestic companies. Ireland's Data Protection Commission leads in total fine value at over EUR 4 billion in aggregate, because major technology companies including Meta, TikTok, LinkedIn, Google, and Apple have their European headquarters in Dublin, making the Irish DPC their lead supervisory authority under the one-stop-shop mechanism.

What are the most common GDPR violations that lead to fines?

The most common violations generating fines are: processing data without a valid legal basis under Article 6; inadequate technical security measures leading to data breaches; unlawful international data transfers without adequate safeguards; failure to respond to data subject rights requests within statutory timeframes; and insufficient transparency in privacy notices. The largest fines have concentrated on international transfers and invalid legal bases for behavioral advertising, and since August 2026 the second-largest fine on record rests on a further theory, the prohibition on fully automated decision-making.

Updates

Corrected: added the Dutch AP's EUR 824,990,000 fine against Uber (imposed August 21, 2026 for fully automated driver deactivations) at rank 2 of the largest-fines table, replaced a tracker status line that still named a EUR 27 million penalty as 2026's largest, and corrected two separate statements that the top three GDPR fines by value all involve cross-border transfers.

Added the Dutch AP's EUR 824,990,000 fine against Uber (imposed August 21, 2026 for fully automated driver deactivations) to the largest-fines table at rank 2, corrected the tracker status line that still described a EUR 27 million CNIL penalty as 2026's largest, and corrected two separate claims that the top three GDPR fines by value all involve cross-border transfers, which was already inaccurate before this fine and is now clearly wrong.

Major expansion: added Deutsche Wohnen CJEU ruling (Dec 2023), updated all major fines with appeal status (Amazon EUR 746M annulled March 2026; TikTok EUR 530M under appeal; Meta EUR 1.2B appeal pending), added Article 82 civil compensation section, [GDPR](/world-laws/world-data-privacy-laws) Omnibus IV reform proposals, and 2025 enforcement statistics from EDPB Annual Report.

Sources and References

  1. GDPR Full Text — Articles 83 and 82(eur-lex.europa.eu).gov
  2. EDPB Guidelines 04/2022 on Calculation of Administrative Fines (final version, June 2023)(edpb.europa.eu).gov
  3. EDPB — EUR 1.2 Billion Fine for Facebook (Binding Decision, May 2023)(edpb.europa.eu).gov
  4. EDPB — Irish SA Fines TikTok EUR 530 Million (May 2025)(edpb.europa.eu).gov
  5. Irish DPC — TikTok EUR 530 Million Decision (May 2025)(dataprotection.ie).gov
  6. Dutch AP — EUR 290 Million Fine on Uber (August 2024)(autoriteitpersoonsgegevens.nl).gov
  7. Irish DPC — LinkedIn EUR 310 Million Fine (October 2024)(dataprotection.ie).gov
  8. CJEU — C-807/21 Deutsche Wohnen Judgment (December 2023)(curia.europa.eu).gov
  9. CJEU — C-300/21 Österreichische Post Judgment (May 2023)(curia.europa.eu).gov
  10. EDPB CEF 2026 — Coordinated Enforcement on Transparency(edpb.europa.eu).gov
  11. European Commission — Enforcement and Sanctions Explainer(commission.europa.eu).gov
  12. EDPB and EDPS Opinion on GDPR Omnibus IV Simplification Proposals (2025)(edpb.europa.eu).gov
  13. GDPR Enforcement Tracker — Live Fines Database(enforcementtracker.com)
  14. DLA Piper GDPR Fines and Data Breach Survey January 2026(dlapiper.com)
  15. CNIL sanction decision: Free and Free Mobile (January 2026)(cnil.fr).gov
Share: